Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-3045

Опубликовано: 08 мар. 2012
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4libpngWill not fix
Red Hat Enterprise Linux 4libpng10Will not fix
Red Hat Enterprise Linux 5libpngFixedRHSA-2012:040720.03.2012
Red Hat Enterprise Linux 6libpngFixedRHSA-2012:040720.03.2012

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=799000libpng: buffer overflow in png_inflate caused by invalid type conversions

EPSS

Процентиль: 89%
0.04701
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 13 лет назад

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.

CVSS3: 8.8
nvd
около 13 лет назад

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.

CVSS3: 8.8
msrc
8 дней назад

Описание отсутствует

CVSS3: 8.8
debian
около 13 лет назад

Integer signedness error in the png_inflate function in pngrutil.c in ...

CVSS3: 8.8
github
около 3 лет назад

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.

EPSS

Процентиль: 89%
0.04701
Низкий

5.1 Medium

CVSS2